I've successfully set up DNN 4.03 to authenticate to our AD domain, so that it recognizes the user as soon as DNN is accessed. However, I'm a little fuzzy on how it all works, i.e. I've noticed that domain administrators are automatically made an admin in DNN. How do you reconcile AD groups with DNN? - Can I create a DNN group in AD that DNN will use?
What does (in Admin, Authentication) 'Synchronize Roles' do? I thought if I unchecked this then domain admins might not automatically be added to DNN Admin, but I thought wrong.